Researchers Discover MediaTek Chip Vulnerability That Could Impact Millions of Android Phones

Security researchers at Ledger Donjon were able to breach an Android phone’s security within 45 seconds.

Advertisement
Written by Dhruv Raghav, Edited by David Delima | Updated: 12 March 2026 17:33 IST
Highlights
  • MediaTek chipsets use Trustonic’s TEE to protect data
  • Researchers were able to access the phone’s security PIN
  • CMF Phone 1 is powered by a MediaTek Dimensity

MediaTek's flagship Dimensity 9500 chip was launched last year

Photo Credit: MediaTek

Researchers at a cryptocurrency firm have discovered a new vulnerability that could allow malicious actors to gain access to Android smartphones in under a minute. The flaw is said to affect MediaTek's Dimensity and Helio chips on some smartphones, by targeting the trusted execution environment that protects sensitive user data on a smartphone. On the other hand, smartphones from other brands like Google, Apple, and various handsets with Snapdragon chips are equipped with dedicated security chips that can protect user information.

MediaTek Vulnerability Allows Data Access Even When Phones Are Shut Off 

In a post on X, Ledger's Chief Technology Officer (CTO) Charles Guillemet claims that Ledger Donjon, the cryptocurrency firm's division of security researchers, has discovered a vulnerability that could affect millions of Android smartphones powered by MediaTek chipsets. The issue appears to stem from the Trustonic TEE, a code execution environment used by MediaTek's Dimensity and Helio series chipsets to protect sensitive data on Android handsets.

Advertisement

The group tested the vulnerability on the CMF Phone 1, which is equipped with a MediaTek Dimensity 7300 chipset. The group was reportedly able to breach the smartphone's security and access the information within 45 seconds of it being plugged into a computer. However, it's worth noting that any Android smartphone with an affected MediaTek chip could be impacted by the flaw.

The researchers could exploit the vulnerability to gain access to the MediaTek chipset-powered Android smartphone's security PIN. They could also access the phone's decrypted storage while also extracting the seed phrases of “the most popular software wallets”, which are 12 to 24-word passwords used for cryptocurrency verification and account recovery.

Advertisement

The executive claims that the security researchers did not even have to turn on the phone to recover the sensitive data. Since the vulnerability may expose “millions of Android phones” to security risks, bad actors can potentially gain access to a user's cryptocurrency wallet and execute transactions without the knowledge of the victim.

At the time of publishing, OEMs have yet to publicly acknowledge this vulnerability. MediaTek told Android Authority that it issued a patch for the vulnerability to device makers as early as January, but it is currently unknown whether smartphone makers have patched the issue for all affected devices.

 
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Swappable rear panel
  • Vibrant 120Hz AMOLED display
  • Good performance
  • Clean User Interface
  • Bad
  • No charger in the box
  • No stereo speakers
  • No dedicated wide-angle or telephoto lens
 
KEY SPECS
Display 6.70-inch
Processor MediaTek Dimensity 7300
Front Camera 16-megapixel
Rear Camera 50-megapixel + 2-megapixel
RAM 6GB, 8GB
Storage 128GB
Battery Capacity 5000mAh
OS Android 14
Resolution 1080x2400 pixels
NEWS

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Z11x 5G Launched in India With a 7,200mAh Battery at This Price
  2. OnePlus 15T Appears in Livestream Ahead of Launch, Key Specifications Revealed
  3. Here's How Much the Poco X8 Pro series Could Cost in India
  4. Motorola Edge 70 Fusion+ Launched With Three Rear Cameras, 5,200mAh Battery
  5. WhatsApp to Now Warn Users About Suspicious Device Linking Attempts
  6. Samsung Galaxy A37 5G Design, Colourways Leaked Again Ahead of Launch
  7. Space Marine 2, Persona 5 Royal and More Join PS Plus Game Catalogue in March
  8. Here's Why the iPhone 18 Pro Might Not Sport a Redesigned Dynamic Island
  9. Vivo X300s Confirmed to Feature 7,100mAh Battery, Gaming Optimisations
  1. Motorola Edge 70 Fusion+ Launched With Triple Rear Camera Setup, 5,200mAh Battery: Price, Features
  2. Metaplanet Announces JPY 4 Billion Venture Arm to Support Japan's Startups, Bitcoin Infrastructure
  3. India Prepares Smartphone Export Incentives in a Boost for Apple
  4. Nvidia Unveils Nemotron 3 Super Open-Source AI Model for Agentic AI Systems
  5. Daredevil Born Again Season 2 OTT Release Date: When and Where to Watch it Online?
  6. Madam Sengupta Hindi Dub Available for Streaming on This Platform: What You Need to Know
  7. Maamla Legal Hai Season 2 OTT Release Date: When and Where to Ravi Kishan Starrer Courtroom Comedy Online?
  8. Researchers Discover MediaTek Chip Vulnerability That Could Impact Millions of Android Phones
  9. Bonk.fun Domain Hijacked in Wallet Drainer Attack Designed to Target Solana Users
  10. PS Plus Game Catalogue Lineup for March Revealed: Space Marine 2, Persona 5 Royal, Madden NFL 26 and More
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.